All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Hackers Use BNB Chain to Spread Malware Via Fake CAPTCHAs

Created at 7 Aug · 4:41 PM1 source↑ Market-relevant
IN SHORT

Cybercriminals are leveraging BNB Smart Chain contracts to store malware instructions, which are then delivered to victims through fake CAPTCHA prompts on compromised websites. This technique, known as EtherHiding, makes it difficult to remove malicious commands and can lead to credential theft and network compromise.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Who's Involved

Microsoft Threat Intelligence
reported on the campaign using BNB Chain for malware distribution
BNB Chain
used by hackers to store malware instructions
ClearFake
malware campaign previously linked to the BNB Chain contracts
Omnistealer
malware that used BNB Chain to steal credentials
Hackers Use BNB Chain to Spread Malware Via Fake CAPTCHAs

↳ Why This Matters

The use of blockchain technology like BNB Chain to host malware instructions presents a significant challenge for cybersecurity defenses, as it makes malicious code more persistent and harder to eradicate. This sophisticated attack vector can lead to widespread credential theft and compromise of sensitive corporate networks.

Key facts

  • Hackers are utilizing BNB Smart Chain contracts to store and distribute malware instructions.
  • Victims are prompted by fake CAPTCHAs to paste malicious commands into Windows tools like Run, Terminal, or PowerShell.
  • The EtherHiding technique embeds malicious instructions within blockchain smart contracts, making them resistant to conventional takedowns.
  • Successful exploitation can lead to credential theft, persistent network access, and potential ransomware attacks.
  • Microsoft has observed thousands of enterprise and consumer devices targeted daily by these campaigns.

Cybercriminals are exploiting BNB Smart Chain contracts to host malware instructions, which are then delivered to unsuspecting users through fake CAPTCHA prompts on compromised websites. This method, identified by Microsoft Threat Intelligence as EtherHiding, embeds malicious commands within blockchain smart contracts, making them difficult to remove and evade traditional security measures.

Victims are enticed by deceptive CAPTCHA challenges to execute commands via Windows tools such as the Run dialog, Windows Terminal, or PowerShell. This technique, referred to as ClickFix and TerminalFix, relies on user interaction to initiate the malware. Once executed, these commands can steal credentials, establish persistent access to corporate networks, and facilitate further malicious activities like ransomware deployment.

Microsoft researchers noted that this approach is a high-volume initial access technique, with campaigns targeting thousands of devices globally each day. The attackers leverage legitimate Windows tools, including PowerShell, cmd, and others, to hide their malicious activities. The use of blockchains to support malware command and control is not a new phenomenon, with previous instances involving Bitcoin and TRON blockchains for similar purposes.

This campaign follows the ClearFake malware's use of EtherHiding in September 2023, and the Omnistealer malware's utilization of BNB Chain, TRON, and Aptos in April 2026 to steal sensitive data. Microsoft recommends that organizations restrict the use of unnecessary command-line tools, enable PowerShell logging, and implement application controls to mitigate these threats. Users are strongly advised against pasting commands from unsolicited sources into system tools.

Frequently asked questions

EtherHiding is a technique where hackers store malicious instructions in a blockchain smart contract, making them difficult to remove and harder for security systems to detect.

Hackers inject JavaScript into compromised websites that contacts a BNB Chain gateway to retrieve commands from a smart contract. Victims see fake CAPTCHAs that instruct them to paste these commands into Windows tools.

Successful infections can lead to the theft of passwords and credentials, establish lasting access to corporate networks, and potentially result in ransomware or broader network compromise.

No, the use of blockchains like Bitcoin and TRON to support malware attacks has been observed in previous campaigns, such as the Glupteba botnet and the Omnistealer malware.

What Happens Next

01Microsoft advises organizations to restrict unnecessary command-line tools.
02Microsoft recommends enabling PowerShell logging.
03Microsoft suggests implementing application controls.
04Users are warned against pasting commands from CAPTCHAs or unsolicited sources.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence
CME Headlines
  • Product Modification Summary: Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether — Effective August 10, 2026
    6 Aug · 7:45 PM
  • Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether
    5 Aug · 7:15 PM

How It Developed

Hackers are using BNB Chain contracts to store malware instructions.
Fake CAPTCHA prompts trick victims into pasting malicious commands into Windows tools.
This technique, known as EtherHiding, makes malware instructions difficult to remove.
Successful infections can steal credentials and grant hackers persistent access to corporate networks.
Microsoft has reported thousands of devices globally are targeted daily by such campaigns.
Previous campaigns have used blockchains like Bitcoin and TRON for similar malicious purposes.

Sources

T1
Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAsDecrypt

Related Stories

Coldcard exploit contributes to $247M in July crypto thefts
7 Aug · 8:11 AM
Russia shuts down 9 unregistered crypto exchanges linked to Ukraine
7 Aug · 12:46 PM
Japan FSA asks crypto exchanges to impose withdrawal delays to fight scams
7 Aug · 5:31 AM
Bybit sues North Korea, Lazarus Group over $1.5B hack, secures asset freeze
7 Aug · 4:41 PM
Bitcoin ETFs See $800 Million Inflow After Coldcard Exploit
7 Aug · 4:06 PM